Skip to content
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
nextbyte.live nextbyte.live
nextbyte.live nextbyte.live
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
Subscribe
Close

Search

nextbyte.live nextbyte.live
nextbyte.live nextbyte.live
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
US Indicts Russian National Over Malware Campaign Targeting 80,000 Freelancers
cybersecurity

US Indicts Russian National Over Malware Campaign Targeting 80,000 Freelancers

By abde el aziz
September 2, 2026 2 Min Read
0

A California federal grand jury has indicted a Russian national for orchestrating a phishing campaign that infected approximately 80,000 freelancers with TVRAT and DarkVNC malware. The Russian malware indictment marks a significant enforcement action against cybercriminals targeting the gig economy workforce.

Table of Contents

  • How the Russian malware indictment unfolded
  • Data theft and criminal infrastructure

Searzhudin Tamirlanovich Aktulaev, 40, was arrested at Larnaca Airport in Cyprus in May 2025 and subsequently extradited to the United States. Court documents filed in June 2021 and unsealed this week detail how the defendant exploited an online messaging platform belonging to an unnamed freelance employment technology company based in the Northern District of California.

US Indicts Russian National Over Malware Campaign Targeting 80,000 Freelancers

How the Russian malware indictment unfolded

Between June 2016 and November 2017, Aktulaev operated 255 fake user accounts to distribute his attack. He sent Microsoft Excel attachments containing malicious macros to 80,000 freelancers. When victims opened these files, the macros automatically downloaded malware onto their systems without additional user interaction.

The Russian malware indictment reveals that Aktulaev deployed two distinct tools to compromise his targets. TVRAT (also known as TeamSPy and TVSPY) and DarkVNC both granted him remote control over infected machines through legitimate remote administration software—TeamViewer and VNC Viewer respectively. This approach allowed him to operate undetected within victim systems.

Data theft and criminal infrastructure

According to the Department of Justice, both malware variants sent stolen data to command-and-control servers operated by Aktulaev and his co-conspirators. The stolen information was then used to commit fraud and other criminal activity. Investigators discovered that Aktulaev stole e-commerce login credentials and personally identifiable information from his victims, with roughly half of all infected machines located in the United States.

The infrastructure supporting this operation was deliberately obscured. Command-and-control domains were paid for using virtual currency, and thousands of infected computers “called back” to a command-and-control domain hosted within the United States itself. This follows a pattern seen in related developments, such as CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks which highlighted how attackers exploit legitimate infrastructure for malicious purposes.

Aktulaev remains in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5. The case reflects broader law enforcement efforts against cybercriminals; as covered earlier, NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions demonstrated how attackers continue to evolve their targeting methods against enterprise users.

المصدر: BleepingComputer

Author

abde el aziz

Follow Me
Other Articles
Samsung expands Android 17 One UI 9 beta to more Galaxy phones
Previous

Samsung expands Android 17 One UI 9 beta to more Galaxy phones

OpenAI faces 30 new lawsuits over Tumbler Ridge shooting claims
Next

OpenAI faces 30 new lawsuits over Tumbler Ridge shooting claims

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • New BambooToken Malware Uses MQTT to Control Windows and Linux Systems
  • Apple rolls out iOS 27 with Siri AI beta
  • Is the GTA 6 Ultimate Edition worth the extra cost?
  • Apple CEO discusses why iPhone Duo foldable arrived after Android rivals
  • Google launches Gemini app for Windows

Recent Comments

  1. New BambooToken Malware Uses MQTT to Control Windows and Linux Systems on CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks
  2. Apple rolls out iOS 27 with Siri AI beta on Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase
  3. Is the GTA 6 Ultimate Edition worth the extra cost? on Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase
  4. Apple CEO discusses why iPhone Duo foldable arrived after Android rivals on The Era of Cheap Smartphones Is Over as Price Hikes Become Permanent
  5. Google launches Gemini app for Windows on Google AI Mode adds flight price tracking and hotel booking tools

Archives

  • September 2026
  • August 2026

Categories

  • ai
  • crypto
  • cybersecurity
  • gadgets
  • hardware
  • tech
  • web
Copyright 2026 — nextbyte.live. All rights reserved. Blogsy WordPress Theme